Medium severity4.3NVD Advisory· Published Mar 1, 2025· Updated Apr 15, 2026
CVE-2024-13546
CVE-2024-13546
Description
The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.1 via the 'get_image_description' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the content of private, draft, and scheduled posts and pages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=1.9.1+ 1 more
- (no CPE)range: <=1.9.1
- (no CPE)range: <=1.9.1
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/browser/generateblocks/trunk/includes/class-dynamic-content.phpnvd
- plugins.trac.wordpress.org/browser/generateblocks/trunk/includes/class-dynamic-content.phpnvd
- plugins.trac.wordpress.org/changeset/3239461/nvd
- www.wordfence.com/threat-intel/vulnerabilities/id/4f6f2a8c-ecd9-482c-a32e-0c3d7a7e4ec4nvd
News mentions
0No linked articles in our index yet.